But you should change the password first on the website rather than change it on the vault first.
If you change it in the vault first you would not be able to log in into the website to change it.
If you press the change button (I suppose you are referring to the At-risk passwords), the website that the password belong to is opened. In this way you have a chance to chance the password on the website.
At this point if the browser extension detects that you are changing the password, it will ask you if you want to update the password stored in the vault with the new one.
If the extension did not detect the change, logout from the website and log in again - if you have your new password copied, you can just paste it. At this point the extension should detect the change and prompt you.
I would like a Delete on the Security Dashboard list of passwords that need to be reviewed. When I click the change password button I am finding that the accounts are no longer active. I want to delete the entire Lastpass entry, but it is quite the pain in the arse to do so. If the site no longer exists, then you have to click on the LP icon, search by title, click edit and then click delete. The password review process would be so much simpler if after discovering that the site no longer exists or that the account has been closed, I could just go back to the Dashboard and click a Delete Record button.